Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Okay so I'm gonna open up a web browser from P.S. 1 to the server the service IP address and this is
a linux server is 10 dot 1 dot wondered 100.
I used the command I have config to see the service IP address.
So what I'll do is start capturing traffic between the P.C. and the switch.
Genius 3 makes this very easy.
It allows us to capture traffic directly within the topology rather than having to install a hub or
a wire tap or something to see the traffic.
So I'm gonna capture the traffic between the P.C. and the switch and we'll be able to see exactly what's
going on within this why shock capture so you can see that we've got spanning tree traffic we've got
a job P traffic dynamic trunk protocol traffic already displayed and being captured by a y shock.
What I'm going to do however is falter for HDP.
There's no HDP traffic at the moment but what we'll do is open up a web browser on the P.C. and connect
it to the server so let's use P.S. 1 open up a web browser.
I'm going to browse to
tendered wondered one at 100 which is the server and as you can see they are web pages displayed.
That's nothing fancy it's just a basic Web page hosted on the server but it's enough for us to see what's
going on.
So in why a shock you can see that traffic was sent from a source IP address 10 1 1 1 to a destination
IP address of 10 1 1 100.
This is HDP traffic.
You can see the protocol they is HDP.
You can see the length you can see that it's an HDP get.
In other words the piece he's trying to get a web page from the server.
Now before I go through the wash capture in more detail let's explain some of the basics that you see
in why shock.
The first thing you see is a frame now in networking.
This is known as Layer two of the oversized model.
Information captured here are known as frames.
So this is known as a frame.
We've captured and Ethernet to frame.
In other words we've captured traffic on Ethernet that different types of Ethan at frames.
But Ethan it too is the most common the source MAC address is a VM where host destination MAC addresses
this.
So the source MAC address is the P.C..
This piece is actually running inside a VM where I type IP conflict slash all you'll be able to see
the MAC address of the host 0 0 0 c 29 ending in DC D 7 and hopefully that's what we see over here.
So notice MAC address is DC D7.
So notice this MAC address is the MAC address of the P.C. destination address is this.
That's the MAC address of the server.
Notice the MAC address over here 36 E four five C 40 91 82.
There you go.
That's the IP address of the server MAC address of the server.
Here's the IP address of the P.C. and the MAC address of the P.C..
So in networking we use the term frame to layer two you get different types of frames on Ethernet typically
Ethan at two.
But on a when connection or wide area network connection you could be using something like point to
point protocol or PDP or HDFC or in the old days you had encapsulation like frame relay or A.T.M..
In other words the layered to frame changes depending on the physical technology that you're using.
Most common technology today's Ethernet most common Ethan at frame type is Ethernet too.
So this is known as a frame not just to make it more confusing in why a shock they talk about frames
here as well but this is actually just metadata used within why shock.
That tells us about the frame.
So again this is just metadata we don't typically talk about that as a frame in networking.
This is known as a frame.
This is known as layer two in the OSA model.
Now I've included a section following this video that talks about ISI and the ISI model.
So if you're not used to the ISI model or you're not quite sure what it's about.
Have a look at those videos.
If you know about the ISI model then skip those videos.
And again if you want more information have a look at my CCN a course.
So this is a frame at least three we have what's called a packet.
So when we refer to the layers in the OS model we use terms such as frame at least two packets layer
three and segment at the layer for at least three we've captured the IP version 4 addresses.
So this is IP version for information.
The protocol used jet layer 4 is IP version for what we'll do actually.
This point is stop my wife's shock capture so that the capture that I share with you isn't too big.
And I'll save this as basic why a shock capture one notice it's a pickup in G file will pick up next
generation Y shock file.
So that's the file that you'll download and you'll be able to do something similar to what I've done
here.
So again protocol at layer 3 is IP version for source IP addresses this destination ip addresses this
IP version 4 contains a lot of information differentiate services code points or differentiate services
field DCP differentiated services code points is to do with quality of service quality of service or
cause or QS allows us to differentiate some traffic types from others.
So in other words we could say that voice traffic is more important than FCP traffic.
So when you make a voice call it should be proud to arised over file transfer protocol or FCP traffic.
This is a way to indicate to the network how important the traffic is.
A lot of other information is shown in this header including as an example that the protocol used at
Layer 4 is TTP.
So lay off for once again this is layered to frame Layer 3 is packet layer forward segment at Layer
4 in the OSA model we are using TTP here and you can see source and destination port numbers HDP or
Hypertext Transfer Protocol uses the well-known port number of 80.
The server was listening on port 80.
That's why when the client made a connection to the server the web page displayed the client initiated
a session to port 80.
The server was listening on port 80.
It served because it's a server.
It served a web page to the client.
In this case using the protocol HDP so it basically has this page.
This web page hosted on its harddrive and it served that page to the client when the client connected
on port 80.
The client uses this random pulled number or ephemeral port number to use the correct term so it connects
to the server using an ephemeral or random port number going to a well-known port number of 80 and then
you can see here the application used his Hypertext Transfer Protocol.
Now in networking we talk about the OS model but typically it's a hybrid model between the TTP model
and the OS side model.
At the top of the other some model we have application presentation and session.
Those layers are often grouped into a single layer called application.
So notice we have Layer 2 here Layer 1 is the physical medium so that's not shown in the wide shot capture
the physical medium here is Ethan it could be copper or could be fiber.
In our example this is just a virtual network.
But in the real world this would be physical Ethernet.
In this case perhaps copper so the physical media is copper.
So that's the physical connection gets just a virtual logical connection.
So layer one physical layer to data link or in this case it's Ethernet Layer three is network.
In this case we've got IP layer four is transport.
In this case it's TTP and then the top three layers are kind of combining to one layer application layer.
So notice Hypertext Transfer Protocol.
And inside here we can see details such as the client used.
It shows up store as windows in t 10 when 64 bit using a browser Mozilla 5.0 so in this example I'm
actually using Microsoft Edge.
That's the browser used within Windows 10.
So this is a Windows 10 a virtual computer.
In other words it's a virtualize.
I'm actually running on a Mac here recording on a Mac but I'm running VMware which allows me to virtualize
multiple devices within my genius free topology.
So the why shock capture sees the client as a Windows 10 computer which is correct using 64 bit Windows
Mozilla is the browser.
It's actually Microsoft Edge and then the server replies back.
Notice in the server example the MAC addresses all swapped round.
In this example I've got a layer to switch a layer to switch means that it's just simply switching trains.
In other words Layer 2 data from one port to another.
It's not trying to rupture the data from one network to another.
These two hosts are in the same subnet or the same network.
So the switch simply switching the traffic from one port to another.
So in this example the IP addresses are swapped round and so are the MAC addresses going back to the
first example.
Notice source MAC address is this destination MAC addresses this when the server replies.
Those are simply stopped around so the server is replying with its MAC addresses the source destination
MAC address is the Windows computer IP addresses a swapped round and so a port numbers and if we look
at the hypertext protocol notice we can see service says 200 Okay 200 means that the server was able
to provide the data to the client.
We didn't have a 4 0 for each team all error.
As an example some data was provided to the client.
Notice you can see here the actual web page that was served to the client so you can see it says network
has toolkit.
You can see the P and G file notice network is toolkit.
And if I look at that web page on the client notice you can see the output here.
It says w w w files located at a var w w w dot HMO and if we look here that's actually what you see.
Files located at var w w w dot HMO.
So if I scroll to the right notice you see the full output.
You get to route after logging in noticed we told you can place files in t t p boot and that's exactly
what you see over here.
So why shock has read the HDP traffic.
Be careful with HDP it's clear text so through why shock you can see exactly what's going on here.
The client is trying to get the G image so it's trying to get the actual P G image and had the server
which is in a boon to server is providing the PMG file so that's the actual file and you can actually
export that and I'd do this again in other videos but let's do it right now.
Genus 3.
Image Some would export that to my desktop and on my desktop I'm going to change that to a PMG file
and then when I open it up notice there's the actual image.
So why shock captured all the data from the server as well as the image.
And that's the image that we have on the server.
So once again to do that click portable network graphics because it's a pinkie file and then go export
packet bytes save it to your hard drive someone to save it once again is genius free image to and then
I'm gonna rename it so it saved it as a burn file.
I'm gonna rename that as P and G because it's a P G file and they want to open it up you can see that
it's say P G file and there's the actual image.
So you can see here it's getting the fave icon and then we're getting something HDP forward for error
something not found.
So something went wrong here.
But the point is is that you can read the actual HDP traffic and remember because of these devices on
the same subnet all that happens is the MAC addresses are swapped around IP addresses or swapped round
port numbers or swapped around during that communication.
So source IP is host yes source IP is the server.
So when the server replies back it's replying back from port 80 to the client.
So that was a very basic example of using Y shock to see what's going on in the network.
Were you able to download the pick up file.
Were you able to open it up in y shock and actually do something similar to what I've done here.
There's no better way to learn than to practically use Y shock capture frames and see for yourself what's
going on.
I've made it a little bit more simple by giving you some pick up files but hopefully they mean something
because she's using the actual files that I'm recording right now rather than just some random file
that you got off the Internet.
Now please note it means a lot to me if you provide feedback on the course.
So if you're enjoying the video then please say so.
If you get prompted to leave a review and you're enjoying the course then please do that because it
helps other students and helps me make the course better let me know how I can improve the course as
well.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.